rankrat
Query Google Search Console, Google Tag Manager, Bing Webmaster Tools, GA4, Microsoft Clarity, PageSpeed, CrUX, Cloudflare analytics, and Bing backlink intelligence; manage typed tags and safe edge redirects; run Lighthouse and bounded whole-site/internal-link audits; persist monitors and issue history; automate ownership and finite remediation through one self-hosted MCP server. Speaks MCP over stdio and Streamable HTTP, plus a FastAPI JSON API. Use when the user wants to inspect or improve SEO, indexing, ownership, internal links, tags, redirects, backlinks, browser scores, performance history, or search traffic for sites they control. Skill: rankrat Owner: psyb0t Summary: Query Google Search Console, Google Tag Manager, Bing Webmaster Tools, GA4, Microsoft Clarity, PageSpeed, CrUX, Cloudflare analytics, and Bing backlink intelligence; manage typed tags and safe edge redirects; run Lighthouse and bounded whole-site/internal-link audits; persist monitors and issue history; automate ownership and finite remediation through one self-hosted MCP server.
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
0.20.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.20.1release · observed Oct 10, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:rankrat- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-rankrat/snapshot"
Documentation
CLAWHUB
150,453 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: rankrat
description: Query Google Search Console, Google Tag Manager, Bing Webmaster Tools, GA4, Microsoft Clarity, PageSpeed, CrUX, Cloudflare analytics, and Bing backlink intelligence; manage typed tags and safe edge redirects; run Lighthouse and bounded whole-site/internal-link audits; persist monitors and issue history; automate ownership and finite remediation through one self-hosted MCP server. Speaks MCP over stdio and Streamable HTTP, plus a FastAPI JSON API. Use when the user wants to inspect or improve SEO, indexing, ownership, internal links, tags, redirects, backlinks, browser scores, performance history, or search traffic for sites they control.
homepage: https://github.com/psyb0t/rankrat
user-invocable: true
metadata:
openclaw:
emoji: "🐀"
requires:
bins: [docker]
permissions:
network: "outbound HTTPS to configured Google Search Console, Google Analytics, Google Tag Manager, Bing Webmaster Tools, Microsoft Clarity, PageSpeed/CrUX, Cloudflare, public DNS, public pages beneath configured sites, and IndexNow endpoints; optional Lighthouse browser traffic to explicitly requested bounded pages; inbound only on the port you bind."
shell: "docker run invocations for the published image or the installed rankrat launcher; no other host access is required."
filesystem: "reads provider-account config and credentials; writes the configured OAuth token store, persistent SQLite monitor state, locally initialized IndexNow key, and discovered resource inventory in the config file when writable."
---
# rankrat
A self-hosted MCP server over the SEO and search-analytics APIs you already have
accounts on — Google Search Console, Google Tag Manager, Bing Webmaster Tools,
GA4, Microsoft Clarity, and PageSpeed Insights — so an agent can read and,
when trusted, manage your own provider resources without you handing it a
browser session or a service-account key.
Install, credentials and the full environment reference:
[`references/setup.md`](references/setup.md).
For a human-readable operator manual organized by topic, use the public
[Rankrat documentation](https://github.com/psyb0t/rankrat/tree/main/docs).
## Contents
- [Security and safety](#security-and-safety)
- [When to use](#when-to-use)
- [When NOT to use](#when-not-to-use)
- [Usage](#usage)
## Security and safety
Configured provider credentials are Rankrat's authority. A Google OAuth account,
Bing key, Cloudflare token, or Clarity project token can reach every supported
resource that provider exposes to it. Resource arrays in the config are
discovered inventory and URL-containment data, not a second permission system.
Fixed provider origins, typed requests, public-URL validation, and child-URL
containment still apply.
Rankrat is **writable by default**. `RANKRAT_READ_ONLY=true` removes every write
tool from `tools/list` and every write route from runtime OpenAPI, including
site onboarding. This is the only capability switch. The human decides whether
the calle_meta.json
{
"ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
"slug": "rankrat",
"version": "0.20.1",
"publishedAt": 1791644028619
}references/setup.md
# rankrat — setup reference Everything the [skill](../SKILL.md) needs but does not need loaded up front: configuration, credentials, and how to run it. This file is the self-contained agent reference shipped with the skill. Human operators can use the topic-based [public manual](https://github.com/psyb0t/rankrat/tree/main/docs), especially [Getting started](https://github.com/psyb0t/rankrat/blob/main/docs/getting-started.md), [Providers and credentials](https://github.com/psyb0t/rankrat/blob/main/docs/providers.md), and [Troubleshooting](https://github.com/psyb0t/rankrat/blob/main/docs/troubleshooting.md). ## Contents - [Configuration](#configuration) - [The boundary file](#the-boundary-file) - [Write access](#write-access) - [Guided setup](#guided-setup) - [Provider credentials](#provider-credentials) - [Running it](#running-it) - [Onboarding](#onboarding) - [Complete MCP tool catalog](#complete-mcp-tool-catalog) - [Checking it works](#checking-it-works) ## Configuration All settings are read from the environment with the `RANKRAT_` prefix, so a field named `http_port` is set by `RANKRAT_HTTP_PORT`. The defaults below are the ones in the settings model, not example values. | Variable | Default | Purpose | |---|---|---| | `RANKRAT_HTTP_HOST` | `127.0.0.1` | Listen address in `http` mode. Loopback by default — bind wider only deliberately. | | `RANKRAT_HTTP_PORT` | `8080` | Listen port in `http` mode. | | `RANKRAT_BOUNDARY_FILE` | `/run/config/boundaries.json` | Provider accounts plus discovered resource inventory and URL-containment roots. | | `RANKRAT_SECRET_ROOT` | `/run/secrets` | Directory holding provider credentials. | | `RANKRAT_OAUTH_TOKEN_ROOT` | `/run/oauth` | Directory holding stored Google OAuth tokens. | | `RANKRAT_LOG_FILE` | `/tmp/rankrat/rankrat.log` | Log destination. | | `RANKRAT_LOG_LEVEL` | `INFO` | Standard Python log levels. | | `RANKRAT_LIGHTHOUSE_WORKER_SOCKET` | `/run/lighthouse/lighthouse.sock` | Optional Unix socket for the isolated local Lighthouse worker. Empty disables it. | | `RANKRAT_STATE_DATABASE` | unset | Absolute SQLite path for monitors, snapshots, and issue events. Empty/unset disables persistence. The wrapper sets `/run/state/rankrat.sqlite3`. | | `RANKRAT_SCHEDULER_INTERVAL_SECONDS` | `60` | How often the HTTP process claims due monitors; accepted range 10–3600 seconds. | | `RANKRAT_STATE_RETENTION_DAYS` | `180` | Snapshot/event retention after a monitor run; accepted range 1–3650 days. | | `RANKRAT_ENABLE_OPENAPI` | `false` | Serve the OpenAPI document. | | `RANKRAT_READ_ONLY` | `false` | See "Write access" below. | | `RANKRAT_HTTP_BEARER_SECRET_FILE` | unset | File holding the bearer token required on HTTP requests. Unset means no auth, so only do that on loopback. | The supported names and safe defaults are in `.env.example`. Invalid values for supported settings fail startup instead of being silently accepted. `make run-http` always supplies a bearer-secret file, including for loopback use; a c
skill-card.md
## Description: Rankrat helps agents inspect SEO, search traffic, indexing, site performance, and managed website settings through a self-hosted server for sites their operators control. This skill is ready for commercial/non-commercial use. ## Publisher: [psyb0t](https://clawhub.ai/user/psyb0t) ### License/Terms of Use: MIT-0 ## Use Case: Site owners, SEO practitioners, and developers use this skill to analyze their own search and analytics data, audit website health, and, when authorized, manage tags, redirects, indexing submissions, and monitoring. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Provider credentials grant broad access, and account-changing tools are enabled by default. Mitigation: Grant only needed provider permissions and use RANKRAT_READ_ONLY=true for agents that should not make changes. Risk: An exposed HTTP endpoint could allow unauthorized access to connected accounts. Mitigation: Bind HTTP to loopback or a private network and require a bearer token when others can reach it. Risk: Installer and container image references may change between reviews. Mitigation: Review the installer and pin and verify the exact release or image digest before use. ## Reference(s): - [ClawHub rankrat release](https://clawhub.ai/psyb0t/skills/rankrat) - [Setup and credentials](references/setup.md) - [Rankrat documentation](https://github.com/psyb0t/rankrat/tree/main/docs) ## Skill Output: **Output Type(s):** [Text, Markdown, Shell commands, Configuration guidance] **Output Format:** [Markdown with reports, recommendations, and command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Reports depend on configured provider accounts; account changes require write access.] ## Skill Version(s): 0.20.1 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/psyb0t/skills/rankrat",
"sourceUrl": "https://clawhub.ai/psyb0t/skills/rankrat",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T16:26:43.961Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-rankrat/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-rankrat/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T16:26:43.961Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/psyb0t/rankrat",
"sourceUrl": "https://clawhub.ai/psyb0t/rankrat",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T16:26:43.961Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.20.1",
"href": "https://clawhub.ai/psyb0t/rankrat",
"sourceUrl": "https://clawhub.ai/psyb0t/rankrat",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-10T14:53:48.619Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-rankrat/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-rankrat/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.20.1",
"description": "- Removed the skill-card.md file. - No other user-facing changes.",
"href": "https://clawhub.ai/psyb0t/rankrat",
"sourceUrl": "https://clawhub.ai/psyb0t/rankrat",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-10T14:53:48.619Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
